69 lines
2.7 KiB
Bash
Executable File
69 lines
2.7 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
|
|
set -euo pipefail
|
|
|
|
project_dir=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
|
|
workdir=$(mktemp --directory)
|
|
trap 'rm -rf "${workdir}"' EXIT
|
|
|
|
sh -n "${project_dir}/install.sh"
|
|
bash -n \
|
|
"${project_dir}/pin-images.sh" \
|
|
"${project_dir}/render.sh" \
|
|
"${project_dir}/create-ci-kubeconfig.sh" \
|
|
"${project_dir}/wait-for-deployments.sh" \
|
|
"${project_dir}/test.sh"
|
|
awk -f "${project_dir}/filter-secrets.awk" /dev/null >/dev/null
|
|
|
|
"${project_dir}/render.sh" "${workdir}/dashboard.yaml"
|
|
|
|
if grep -Eq '^kind:[[:space:]]*Secret[[:space:]]*$' "${workdir}/dashboard.yaml"; then
|
|
echo "Restricted CI render contains a Secret" >&2
|
|
exit 1
|
|
fi
|
|
if rg -i 'Bearer [A-Za-z0-9._-]{20,}|token:[[:space:]]*[A-Za-z0-9._-]{20,}' "${project_dir}" \
|
|
--glob '*.yaml' --glob '*.yml'; then
|
|
echo "A bearer token appears to be committed" >&2
|
|
exit 1
|
|
fi
|
|
|
|
grep -Fq 'kubernetes-dashboard-auth-proxy' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"
|
|
grep -Fq 'name: kubernetes-dashboard-authentik' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"
|
|
grep -Fq 'authentik-server.authentik.svc.cluster.local/outpost.goauthentik.io/auth/traefik' \
|
|
"${project_dir}/kubernetes-dashboard-ingressroute.yaml"
|
|
if grep -Fq 'namespace: default' "${project_dir}/kubernetes-dashboard-ingressroute.yaml"; then
|
|
echo "Dashboard route must not use a cross-namespace middleware" >&2
|
|
exit 1
|
|
fi
|
|
if grep -Fq 'rollout status' "${project_dir}/.gitea/workflows/deploy.yml"; then
|
|
echo "Restricted CI must poll exact Deployment names instead of list/watch" >&2
|
|
exit 1
|
|
fi
|
|
grep -Fq 'expirationSeconds: 3600' "${project_dir}/auth-proxy.yaml"
|
|
grep -Fq 'proxy_pass https://kubernetes-dashboard-kong-proxy' "${project_dir}/auth-proxy.yaml"
|
|
grep -Fq 'containerPort: 8443' "${workdir}/dashboard.yaml"
|
|
grep -Fq 'dashboard-api:1.14.0@sha256:2bd14c0ffee99d15fb1595644ebd1083ac32c5157c6e6fd8615b0f556a1390c2' "${workdir}/dashboard.yaml"
|
|
|
|
request_count=$(awk '
|
|
$1 == "cpu:" && $2 == "25m" { count++ }
|
|
END { print count + 0 }
|
|
' "${workdir}/dashboard.yaml")
|
|
if [[ "${request_count}" -lt 5 ]] || grep -Fq 'cpu: 100m' "${workdir}/dashboard.yaml"; then
|
|
echo "Expected every Dashboard chart component to request only 25m CPU" >&2
|
|
exit 1
|
|
fi
|
|
|
|
image=ghcr.io/yannh/kubeconform:v0.7.0@sha256:85dbef6b4b312b99133decc9c6fc9495e9fc5f92293d4ff3b7e1b30f5611823c
|
|
for file in \
|
|
"${workdir}/dashboard.yaml" \
|
|
"${project_dir}/kubernetes-dashboard-user.yaml" \
|
|
"${project_dir}/auth-proxy.yaml" \
|
|
"${project_dir}/kubernetes-dashboard-ingressroute.yaml" \
|
|
"${project_dir}/ci-deployer.yaml"
|
|
do
|
|
docker run --rm --interactive "${image}" \
|
|
-strict -exit-on-error -ignore-missing-schemas -summary < "${file}"
|
|
done
|
|
|
|
echo "Dashboard public desired state is valid and contains no static credentials."
|